Scrappy RAT Malware Targets Chrome And Edge Users

https://hothardware.com/contentimages/NewsItem/71213/content/16x9_2133x1200_highres-rat-malware.jpg

A new remote access trojan (RAT) has been discovered by the cybersecurity research team at Cisco Talos, and experts are sounding the alarm since it enables the installation of ransomware on the victim's system. The attack is dubbed msaRAT and attributed to the Chaos ransomware group, built with Rust to utilize existing Chrome or Edge (Chromium-based) browser installations. By leveraging the browser's ordinary communication methods, msaRAT is able to disguise its traffic with Chrome's DevTools Protocol and enable command-and-control (C2) communications without detection from typical anti-malware or antivirus software.

Once the attackers have successfully infiltrated a target network with msaRAT malware, numerous possibilities emerge. The malware runs via a headless (no window/invisible) browser process and can be used to perform remote code execution on the target machines. Besides opening the door for the Chaos group's ransomware, it also enables covert data theft and more.

While the potential...

Copyright of this story solely belongs to hothardware.com. To see the full text click HERE

Read more